Ring authentication method for concurrency environment
Summary by NHIP
Ring authentication with proof of knowledge
The method provides sender anonymity and deniability in a concurrency environment by exchanging messages between multiple user devices. It certifies the sender through a signature of proof of knowledge using disposable private key/public key pairs generated by the receiver before the certification request.
Claim Score by NHIP
Abstract
A ring authentication method for a concurrency environment, the method capable of providing unforgeability, sender anonymity, and deniability in the concurrency environment, in which, when a receiver receiving a message requests a sender of the message to certify the message, the sender requested to certify the message sends a message certification value certifying that the sender is one of a plurality of users {P1, . . . , Pn} and authenticates the message m to the receiver, and the receiver verifies the sent message certification value and authenticates that the message is sent from the one of the plurality of users {P1, . . . , Pn}.

Term
Projected expiry 20 March 2030.
- Priority
- Filed
- Granted
- Today
- Projected expiry
8 claims: 1 independent, 7 dependent
- 1Broadest claimClaim Score 58, broad(NHIP)A ring authentication method for a concurrency environment, the method comprising:providing a plurality of user devices {P 1 , . . . , P n } including a sender and a receiver, wherein each of the user devices {P 1 , . . . , P n } sends and receives a message with another one of the user devices {P 1 , . . . , P n } to provide sender anonymity;sending a message from the sender to the receiver;requesting the sender to certify the message, the requesting being performed by the receiver;sending a message certification value certifying that the sender is one of the plurality of user devices {P 1 , . . . , P n } and authenticating the message by using a signature of proof of knowledge from the sender to the receiver;and verifying the message certification value from the sender and checking whether the message is authenticated, the verifying and checking being performed by the receiver.
39 paragraphs in 5 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATIONS
This application claims the priority of Korean Patent Application No. 10-2006-0121835 filed on Dec. 4, 2006, and the priority of Korean Patent Application No. 2007-0048106 filed on May 17, 2007, in the Korean Intellectual Property Office, the disclosure of which is incorporated herein by reference.
BACKGROUND OF THE INVENTION
1. Field of the Invention
The present invention relates to a ring authentication method for a concurrency environment, the method capable of providing unforgeability, sender anonymity, and deniability in the concurrency environment.
The present invention was supported by the IT R&D program of MIC/IITA. [Project code: 2005-Y-001-02, Project title: Developments of next generation security technology]
2. Description of the Related Art
Message authentication indicates a technology in which, when a sender sends a message to a receiver, the receiver is capable of confirming an identification (ID) of the sender, which should provide unforgeability, sender anonymity, and deniability.
In this case, the unforgeability indicates that an attacker is incapable of disguising as another user, the sender anonymity indicates that receiver is only known that “a sender of a message is one of n number of users.” but a actual sender is unknown, and the deniability indicates that the attacker is incapable of certifying that “a sender and a receiver authenticate a message.” to another user by using an obtained authentication protocol message.
As a message authentication method, a ring authentication method (CRYPTO 2002, refer to p 481-498) is provided by Moni Naor. The ring authentication method uses that a person who knows a private key corresponding to a public key is capable of correctly extracting a plaintext from a ciphertext. The ring authentication method is formed in such a way that only a person who knows a private key corresponding to at least on public key of several public keys is capable of knowing a correct plaintext.
However, in real life, several sessions may be concurrently performed. The ring authentication method is incapable of providing the deniability when the receiver performs protocols with several senders at the same time.
To provide the deniability in a concurrency environment, a ring authentication method using a ring signature and a chameleon hash function is proposed by Susilio and Mu (ICISC 2003, refer to p386-401). The method proposed by Susilio and Mu uses the ring signature and allows a receiver to know that one user belonging to a certain user set signs. According to the method, a message sender may deny “a message m is authenticated” with respect to a certain message. However, a fact that “a message is authenticated” is incapable of being denied. Accordingly, perfect deniability is not provided.
SUMMARY OF THE INVENTION
An aspect of the present invention provides a ring authentication method for a concurrency environment, the method capable of providing unforgeability, sender anonymity, and perfect deniability in the concurrency environment.
According to an aspect of the present invention, there is provided a ring authentication method for a concurrency environment, the method including: requesting a sender of a message to certify the message, the requesting is performed by a receiver receiving the message; sending a message certification value certifying that the sender is one of a plurality of users {P<sub>1</sub>, . . . , P<sub>n</sub>} and authenticates the message, from the sender requested to certify the message to the receiver by using a signature of proof of knowledge; and verifying the sent message certification value and checking whether the message is authenticated, the verifying and checking is performed by the receiver.
BRIEF DESCRIPTION OF THE DRAWINGS
The above and other aspects, features and other advantages of the present invention will be more clearly understood from the following detailed description taken in conjunction with the accompanying drawing, in which:
<figref idrefs="DRAWINGS">FIG. 1</figref> is a flowchart illustrating a ring authentication method in a concurrency environment according to an embodiment of the present invention.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENT
Exemplary embodiments of the present invention will now be described in detail with reference to the accompanying drawings. Only, in describing operations of the exemplary embodiments in detail, when it is considered that a detailed description on related well-known functions or constitutions unnecessarily may make essential points of the present invention be unclear, the detailed description will be omitted.
In the drawings, the same reference numerals are used throughout to designate the same or similar components.
The present invention may allow a receiver to check that a message m is authenticated by one of users in a predetermined group by using a signature of proof of knowledge, thereby providing sender anonymity simultaneously with perfect deniability.
Hereinafter, to help understanding a ring authentication method according to an exemplary embodiment of the present invention, the signature of proof of knowledge will be described.
Hereinafter, a group generator of a group G whose order is a decimal q is g. A signature of proof of knowledge according to an exemplary embodiment of the present invention is SPK<sub>OR</sub>, which is capable of certifying that a sender knows one or more discrete logarithms of discrete logarithm values {log<sub>g</sub>(y<sub>1</sub>), . . . , log<sub>g</sub>(y<sub>n</sub>)} when a set of elements of a certain group is {y<sub>1</sub>, . . . , y<sub>n</sub>}.
For example, it is assumed that the sender knows x<sub>i*</sub>=log<sub>g</sub>(y<sub>i*</sub>).
In the signature of proof of knowledge, the sender sends σ=(c<sub>1</sub>, . . . , c<sub>n</sub>,s<sub>1</sub>, . . . , s<sub>n</sub>) to a receiver calculated by Equation 1. <br />σ=(<i>c</i><sub>1</sub><i>, . . . , c</i><sub>n</sub><i>,s</i><sub>1</sub><i>, . . . , s</i><sub>n</sub>)=<i>SPK</i><sub>OR</sub>[(α):<i>y</i><sub>1</sub><i>=g</i><sup>α</sup><i>V . . . Vy</i><sub>n</sub><i>=g</i><sup>α</sup>](m) Equation (1)
To generate σ, the sender randomly selects r<sub>i </sub>and (c<sub>i</sub>,s<sub>i</sub>) (1≦i(≠i*)≦n) and calculates c by using Equation 2. <br /><i>c=H</i>(<i>m∥y</i><sub>1</sub><i>∥ . . . ∥y</i><sub>n</sub><i>∥y</i><sub>1</sub><sup>c</sup><sup><sub2>1</sub2></sup><i>g</i><sup>s</sup><sup><sub2>1</sub2></sup><i>∥ . . . ∥g</i><sup>r</sup><sup><sub2>i*</sub2></sup><i>∥ . . . ∥y</i><sub>n</sub><sup>c</sup><sup><sub2>n</sub2></sup><i>g</i><sup>s</sup><sup><sub2>n</sub2></sup>) Equation (2)
c<sub>i* </sub>satisfying
<maths id="MATH-US-00001" num="00001"><math overflow="scroll"><mrow><mi>c</mi><mo>=</mo><mrow><munderover><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mi>n</mi></munderover><mo></mo><mstyle><mspace width="0.3em" height="0.3ex" /></mstyle><mo></mo><msub><mi>c</mi><mi>i</mi></msub></mrow></mrow></math></maths><br /> is calculated, and s<sub>i*</sub>=r<sub>i*</sub>−c<sub>i*</sub>x<sub>i* </sub>is calculated.
On the other hand, the receiver receiving the received σ checks whether the received σ satisfies following Equation 3, thereby certifying that σ=(c<sub>1</sub>, . . . , c<sub>n</sub>,s<sub>1</sub>, . . . , s<sub>n</sub>)=SPK<sub>OR</sub>[(α):y<sub>1</sub>=g<sup>α</sup>V . . . Vy<sub>n</sub>=g<sup>α</sup>](m). <br />(<i>c</i><sub>1</sub><i>+ . . . +c</i><sub>n</sub>)mod <i>q=H</i>(<i>m∥y</i><sub>1</sub><i>∥ . . . ∥y</i><sub>n</sub><i>∥y</i><sub>1</sub><sup>c</sup><sup><sub2>1</sub2></sup><i>g</i><sup>s</sup><sup><sub2>1</sub2></sup><i>∥ . . . ∥y</i><sub>n</sub><sup>c</sup><sup><sub2>n</sub2></sup><i>g</i><sup>s</sup><sup><sub2>n</sub2></sup>) Equation (3)
That is, the receiver may certify that the sender knows one or more discrete logarithms x<sub>i*</sub>=log<sub>g</sub>(y<sub>i*</sub>) of discrete logarithm values {log<sub>g</sub>(y<sub>1</sub>), . . . , log<sub>g</sub>(y<sub>n</sub>)}.
Hereinafter, the ring authentication method using the described signature of proof of knowledge will be described with reference to <figref idrefs="DRAWINGS">FIG. 1</figref>.
In the ring authentication method according to an exemplary embodiment of the present invention, it is assumed that users P<sub>i </sub>sending and receiving a message with another user have a private key/public key pair (x<sub>i</sub>,y<sub>i</sub>=g<sup>x</sup><sup><sub2>1</sub2></sup>), respectively.
A sender, via the present invention, certifies that “The sender is one of {P<sub>i</sub><sub><sub2>1</sub2></sub>, . . . , P<sub>i</sub><sub><sub2>n</sub2></sub>} authenticates a message m.” to a receiver, thereby providing sender anonymity simultaneously with perfect deniability.
Referring to <figref idrefs="DRAWINGS">FIG. 1</figref>, a receiver R receives a message m from a sender P<sub>i </sub>in S<b>11</b> and generates a one-time private key/public key pair (x<sub>R</sub>,y<sub>R</sub>=g<sup>x</sup><sup><sub2>R</sub2></sup>) to authenticate the message m in S<b>12</b>.
In S<b>13</b>, a receiver certification value σ<sub>R </sub>certifying that the generated private key/public key pair is known is generated as shown in following Equation 4. <br />σ<sub>R</sub><i>=SPK</i><sub>OR</sub>[(α):<i>y</i><sub>R</sub><i>=g</i><sup>x</sup><sup><sub2>R</sub2></sup>](<i>m</i>) Equation (4)
In S<b>14</b>, the generated (y<sub>R</sub>,σ<sub>R</sub>=SPK<sub>OR</sub>[(α):y<sub>R</sub>=g<sup>x</sup><sup><sub2>R</sub2></sup>](m)) is sent to the sender P<sub>i </sub>and requests message certification.
The sender P<sub>i </sub>receiving the (y<sub>R</sub>,σ<sub>R</sub>=SPK<sub>OR</sub>[(α):y<sub>R</sub>=g<sup>x</sup><sup><sub2>R</sub2></sup>](m)) verifies σ<sub>R </sub>sent from the receiver R and checks the truth of σ<sub>R </sub>in S<b>15</b>. σ<sub>R </sub>is verified by using Equation 3 described above.
As a result of the checking, when σ<sub>R </sub>is correct, the sender P<sub>i </sub>generates a message certification value σ<sub>s </sub>σ<sub>s</sub>=(c<sub>1</sub>, . . . , c<sub>n</sub>,s<sub>1</sub>, . . . , s<sub>n</sub>)=SPK<sub>OR</sub>[(α):y<sub>1</sub>=g<sup>α</sup>V . . . Vy<sub>n</sub>=g<sup>α</sup>Vy<sub>R</sub>=g<sup>α</sup>](m) for satisfying that one of private key/public key pairs of users is known by using a private key/public key pair (x<sub>i</sub>,y<sub>i</sub>=g<sup>x</sup><sup><sub2>i</sub2></sup>) of the sender P<sub>i </sub>according to Equation 1 in S<b>16</b>, and sends the generated σ<sub>s </sub>to the receiver R in S<b>17</b>.
The receiver R verifies the truth of the σ<sub>s </sub>sent from the sender P<sub>i </sub>by using Equation 3 in S<b>18</b>.
As a result of the verifying, when σ<sub>s </sub>is correct, the receiver R accepts that “The sender P<sub>i </sub>is one of {P<sub>i</sub><sub><sub2>1</sub2></sub>, . . . , P<sub>i</sub><sub><sub2>n</sub2></sub>} and authenticates the message m.” in S<b>19</b>.
Via this, the receiver R may provide perfect deniability simultaneously with authenticating the message m in a concurrency environment, in which sender anonymity may be provided.
As described above, according to an exemplary embodiment of the present invention, when authenticating a message in a concurrency environment, perfect deniability is provided simultaneously with providing unforgeability and sender anonymity. In addition, the ring authentication method according to an exemplary embodiment of the present invention is capable of being embodied as a two-round, thereby providing efficiency similar to or higher than conventional methods.
While the present invention has been shown and described in connection with the exemplary embodiments, it will be apparent to those skilled in the art that modifications and variations can be made without departing from the spirit and scope of the invention as defined by the appended claims.
Contents5
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both waysCites: the store holds 13 of 14
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP1681826A1 | Cites | European Patent Office (EPO) | Applicant |
| KR20030050620A | Cites | Republic of Korea | Applicant |
| US2004030888A1 | Cites | United States of America | Applicant |
| US2007189535A1 | Cites | United States of America | Applicant |
| US2008077791A1 | Cites | United States of America | Search report |
| US2008215549A1 | Cites | United States of America | Search report |
| US2010274783A1 | Cites | United States of America | Search report |
| US4933970A | Cites | United States of America | Applicant |
| US6144944A | Cites | United States of America | Search report |
| US6584447B1 | Cites | United States of America | Search report |
| US6600823B1 | Cites | United States of America | Search report |
| US6941471B1 | Cites | United States of America | Search report |
| JPH09298537A | Cites | Japan | Applicant |
| Moni Naor, "Deniable Ring Authentication", CRYPTO 2002, LNCS 2442, pp. 481-498, Springer-Verlag Berlin Heidelberg. | Non-patent | – | Applicant |
| Willy Susilo and Yi Mu, "Non-interactive Deniable Ring Authentication", ICISC 2003, LNCS 2971, pp. 386-401, Springer-Verlag Berlin Heidelberg. | Non-patent | – | Applicant |
4 members in 2 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 20060121835 | Republic of Korea | A | |
| 20060121835 | Republic of Korea | A | |
| 20070048106 | Republic of Korea | A | |
| 20070048106 | Republic of Korea | A | |
| 1020060121835 | – | – | – |
| 1020070048106 | – | – | – |
| KR20060121835 | – | – | – |
| KR20070048106 | – | – | – |
Members4
| Document | Office | Kind | |
|---|---|---|---|
| US2008133917A1 | United States of America | A1 | |
| KR20080050945A | Republic of Korea | A | |
| KR100901693B1 | Republic of Korea | B1 | |
| US7975142B2This record | United States of America | B2 |
58 transactions on the USPTO file
Allowed after 1 non-final rejection.
- Non-final rejections
- 1
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Expire PatentEXP. | EXP. | |
| Maintenance Fee Reminder MailedREM. | REM. | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Acknowledgement of Priority PapersMP327 | MP327 | |
| Priority Paper AcknowledgementP327 | P327 | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Email NotificationEML_NTR | EML_NTR | |
| Filing Receipt - ReplacementFLRCPT.R | FLRCPT.R | |
| Request from applicant for the USPTO to retrieve the Priority DocumentPDREQUST | PDREQUST | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Sent to Classification ContractorPGPC | PGPC | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Cleared by L&R (LARS)L128 | L128 | |
| Intentionally Referred by OIPE or L&RL127 | L127 | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapsed due to failure to pay maintenance feeLapsedFP | FP | |
| Lapse for failure to pay maintenance feesLapsedPATENT EXPIRED FOR FAILURE TO PAY MAINTENANCE FEES (ORIGINAL EVENT CODE: EXP.); ENTITY STATUS OF PATENT OWNER: SMALL ENTITYLAPS | LAPS | |
| Information on status: patent discontinuationPATENT EXPIRED DUE TO NONPAYMENT OF MAINTENANCE FEES UNDER 37 CFR 1.362STCH | STCH | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: SMALL ENTITYFEPP | FEPP | |
| Fee paymentFPAY | FPAY | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: SMALL ENTITYFEPP | FEPP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication
- 07975142
- Publication, DOCDB
- 7975142
- Publication, EPODOC
- US7975142
- Application
- 11932916
- Application, DOCDB
- 93291607
- Application, EPODOC
- US20070932916
Titles
- English
- Ring authentication method for concurrency environment
Patent term adjustment
- A delay
- +635 daysthe office missed an examination deadline
- B delay
- +247 dayspendency past three years
- Applicant delay
- −11 days
- Net adjustment
- 871 days
Classification
- CPC, 4
- H04L9/3218
- H04L9/3013
- H04L9/3247
- H04L2209/42
- IPC, 1
- H04L9 32
- USPC, 2
- 713175000
- 380030000